<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: fresno]]></title>
    <link>http://securityratty.com/tag/fresno</link>
    <description></description>
    <pubDate>Wed, 20 Feb 2008 22:57:26 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[University of California Irvine students are hit with mysterious breach]]></title>
      <link>http://securityratty.com/article/5b27cd4f47b57d95125f4eac7c9262a2</link>
      <guid>http://securityratty.com/article/5b27cd4f47b57d95125f4eac7c9262a2</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/4/08

Organization
University of California

Contractor/Consultant/Branch
University of California, Irvine (UCI

Victims
current and former UCI...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/uci.jpg" align="right" height="204" width="204"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/4/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.universityofcalifornia.edu/">University of California</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.uci.edu/">University of California, Irvine (UCI)</a> <br><br><span style="font-weight: bold;">Victims:</span><br>"current and former UCI graduate students and medical students"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 100 identified victims at UCI"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Tax information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"April 9 Update: UC Irvine has received more than 100 reports that Social Security numbers have been stolen and used to file fraudulent tax returns to gain refunds."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.uci.edu/identitytheftalert/">University of California, Irvine Identity Theft Alert</a> <br><a href="http://www.ocregister.com/articles/students-uci-henisey-2012204-irs-tax">Orange County Register</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of California, Irvine<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>UC Irvine police say 7,000 current or former graduate students could be at risk of identity thieves who already used stolen data to file fake tax returns<br><br>Victims are identified as current and former UCI graduate students and medical students.<br><br>In most cases, the students have discovered the issue when they electronically submit their federal income tax returns and the Internal Revenue Service informs them that someone has already filed using their name and Social Security number.<br><span style="font-style: italic;">[Evan] Wow!&nbsp; This is a shocking way of finding out that you are a victim.</span><br><br>Police said Friday they don't know how the information was stolen or who is using it.<br><span style="font-style: italic;">[Evan] This is almost equally as alarming.&nbsp; How do you plug a hole if you don't know where it is or if it's even still leaking?</span><br><br>UCIPD sent out a campuswide crime alert March 20 describing the situation and advising students to contact campus police, at 949-824-0073 or (after hours/weekends) 949-824-5223, if they have any information or believe they have been a victim.<br><br>To date, an extensive investigation by the university has not identified a security breach on campus. <br><br>Extensive full-time resources have been dedicated to the investigation. UC Irvine Police Department, Network &amp; Academic Computing Services, Administrative Computing Services and campus administrative staff have been conducting a thorough investigation.<br><br>The only victims of whom UCI is aware are graduate and medical students who were enrolled during the 2006-07 academic year and had GSHIP (Graduate Student Health Insurance Program) insurance.<br><span style="font-style: italic;">[Evan] This is a localized group of people, so you would think that this would narrow the source down some.</span><br><br>Students who fall into that category can call the IRS at 1-800-829-1040.<br><br>"For the last two weeks, we have been scouring all of our databases and computer systems, but we have not found any leak here" on campus, UCI Police Chief Paul Henisey said.<br><br>The thefts appear to be part of a larger national case being investigated by the Internal Revenue Service, Henisey said. IRS agents have been on campus as part of the inquiry, he said. Henisey said the trail leads out of state, but would not comment further to avoid jeopardizing the case.<br><span style="font-style: italic;">[Evan] It is good news that the IRS is working with the case too.&nbsp; I think it is going to take a sound investigation by the IRS to track this down.</span><br><br>Local and federal agencies stand ready to help. File crime reports with:<br>•&nbsp;&nbsp; &nbsp;UCI Police Department, 949-824-5223<br>•&nbsp;&nbsp; &nbsp;IRS, 1-800-829-1040 <br>•&nbsp;&nbsp; &nbsp;Social Security Administration, 1-800-772-1213 <br>•&nbsp;&nbsp; &nbsp;Federal Trade Commission Identity Theft Hotline, 1-877-438-4338 <br>•&nbsp;&nbsp; &nbsp;Credit reporting agencies (see above) <br>Students also may wish to call the IRS’ Taxpayer Advocate office, 1-877-777-4778. <br><br>The IRS has instructed that after the students have filed a crime report with the UC Irvine Police Department, they should complete a paper copy of their tax return, include a note as to what happened that provides the UCI Police Department report (DR) number, and mail the paper return to the IRS’ Fresno office.<br><br>The IRS has reported a significant number of identity theft crimes occurring nationwide, and it is possible that UC Irvine is the victim of one of those criminal enterprises.<br><br>the university’s financial aid office is arranging emergency loans in appropriate amounts for current students who face financial hardship by the delay in receiving their income tax refund<br><span style="font-style: italic;">[Evan] This seems like really good judgment on the part of the school.</span><br><br>Ensuring data security is one of the most important responsibilities we have to the campus community and a top priority. We continually work to strengthen our information security practices.<br><span style="font-style: italic;">[Evan] I really like this statement.&nbsp; The key concepts in this statement that grab my attention are "top priority" and "continually work to strengthen".&nbsp; I couldn't agree more.</span><br><br><span style="font-weight: bold;">Student Reaction:</span><br>Graduate student Stephanie Casey said she didn't know if her identity was stolen, but she's disturbed that the campus has not been telling students to call the credit agencies and put fraud alerts on their accounts.<br><span style="font-style: italic;">[Evan] This statement must have been made without the knowledge that the school has informed students and urged them to call credit agencies.</span><br><br>"All these students don't know how serious it is that their names were sold," Casey said. "UCI is trying to keep it out of the press because it looks horrible for them, but either (an employee) did this or someone they contracted with did this, and they don't want to create mass panic, but this is the kind of thing you should be panicked about."<br><span style="font-style: italic;">[Evan] I included these remarks because I do agree that this seems like an inside job based on the limited information we know.</span><br><br>Henisey said outside contractors are being examined as a possible source for the leak, possibly including those involved with health insurance, employment and unions.<br><br>UCI appears to be the only campus in the UC system or in Orange County that is having the problem, Henisey said.<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach is unnerving in the fact that nobody seems to know how it occurred or is occurring.&nbsp; Victims probably feel helpless and authorities are limited in what they can do to help.&nbsp; All in all, it seems like the school, police and other investigators have done a good job in identifying the problem and responding to it.&nbsp; This has to be a significant challenge for them. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/10/uci.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Apr 2008 08:14:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/irvine">irvine</category>
      <category domain="http://securityratty.com/tag/irvine police department">irvine police department</category>
      <category domain="http://securityratty.com/tag/police">police</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/contact campus police">contact campus police</category>
      <category domain="http://securityratty.com/tag/credit agencies">credit agencies</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/irvine police">irvine police</category>
      <category domain="http://securityratty.com/tag/medical students">medical students</category>
      <source url="http://breachblog.com/2008/04/10/uci.aspx">University of California Irvine students are hit with mysterious breach</source>
    </item>
    <item>
      <title><![CDATA[New parents exposed in Fresno County lost mail]]></title>
      <link>http://securityratty.com/article/4b50b16067e6326c756d635c87b5dba1</link>
      <guid>http://securityratty.com/article/4b50b16067e6326c756d635c87b5dba1</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/3/08

Organization
Fresno County

Contractor/Consultant/Branch
None

Victims
New parents and babies

Number Affected
279

Types of Data
Names and...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/fresno.jpg" align="right" height="77" width="78"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/3/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.co.fresno.ca.us/portal/Default.asp">Fresno County</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>New parents and babies<br><br><span style="font-weight: bold;">Number Affected:</span><br>279<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Fresno County health officials say 279 birth certificate applications that list personal information of Valley babies and their parents are missing after they were mailed to the state. An envelope containing the birth certificate applications arrived at the the state Department of Public Health in Sacramento damaged, but with most of the forms missing."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.mercurynews.com/news/ci_8796927">The Mercury News</a> <br><a href="http://www.fresnobee.com/opinion/story/505256.html">The Fresno Bee</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>The Associated Press<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Fresno County health officials say 279 birth certificate applications that include the Social Security numbers of the babies' parents are missing.<br><span style="font-style: italic;">[Evan] Thankfully, these babies do not have Social Security numbers yet, otherwise this adds a whole new dimension.</span><br><br>The state Department of Public Health told the county in February that an envelope containing 378 birth certificate applications from Fresno County had arrived damaged in Sacramento and that most were missing.<br><br>The forms contain information about babies born in six San Joaquin Valley hospitals, including their parents' names and Social Security numbers.<br><span style="font-style: italic;">[Evan] Again, Social Security numbers used as personal identifiers in a manner that they were never designed for.</span><br><br>State officials called the incident a low risk for identity theft, but parents were notified about the missing forms.<br><span style="font-style: italic;">[Evan] I wonder who makes the judgment call that terms this "low risk".&nbsp; Must be somebody that is well versed in risk management, right?</span><br><br>The Postal Service is searching for the items and trying to figure out where the certified letter was damaged.<br><br><span style="font-weight: bold;">Fresno Bee Opinion Column:</span><br>The latest screw-up by Fresno County is more evidence of how cavalierly county officials treat the public's sensitive personal information. No wonder identity theft is out of control. Our government, at all levels, is a major contributor to the problem.<br><br>Sending this information by mail may not have been the dumbest thing county officials have done lately, but it has to be right up there. Why wasn't this packet sent by courier or some other more secure means?<br><span style="font-style: italic;">[Evan] Like encrypted on a CD or transferred over a secure network.</span><br><br>In February, county officials warned thousands of CalWORKs clients that they could be victimized after a laptop computer was stolen.<br><span style="font-style: italic;">[Evan] We missed this one on <a href="http://breachblog.com">The Breach Blog</a>.&nbsp; I may have to go back an add it now.</span><br><br>The response by county officials is to shrug off these lapses, and offer the standard response that they don't think anyone has been the victim of fraud because of their negligence. How do they really know?<br><br>The security of personal information must have a much higher priority than the Board of Supervisors gives it. The board should be demanding that sensitive information not be put on laptops that can be easily stolen, or bundled up and dropped in the mail -- a packet that can be easily damaged during the mailing process.<br><br>Every year, tens of thousands of Californians become identity theft victims. Thieves create new credit card accounts with stolen Social Security numbers, then rack up huge expenditures on the cards before the victims notice.<br><span style="font-style: italic;">[Evan] Tens of thousands of victims in California, yet people continue to tag breaches as "low risk".</span><br><br>In the San Joaquin Valley, methamphetamine users are glad that Fresno County doesn't have strong security procedures for personal data. Police tell us that 70% of Fresno's identity-theft cases are committed by meth addicts. They stay up for days finding ways to steal personal financial information.<br><br>Fresno County makes it easy for them. <br><br><span style="font-weight: bold;">Commentary:</span><br>Can you imagine the joy that many of these parents feel in bringing home a new baby boy or girl.&nbsp; Now imagine some of the joy being taken away because somebody unnecessarily exposed your personal details.&nbsp; It stinks that terrible security practices have the potential to affect personal lives. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/06/fresno.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 07 Apr 2008 12:07:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/fresno">fresno</category>
      <category domain="http://securityratty.com/tag/fresno county">fresno county</category>
      <category domain="http://securityratty.com/tag/list personal information">list personal information</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <source url="http://breachblog.com/2008/04/07/fresno.aspx">New parents exposed in Fresno County lost mail</source>
    </item>
    <item>
      <title><![CDATA[Clovis Unified School District employees receive notice]]></title>
      <link>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</link>
      <guid>http://securityratty.com/article/662c821c98ea5a31b7ba3df83725eae5</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
2/16/08

Organization
Clovis Unified School District

Contractor/Consultant/Branch
Systematic Automation

This breach is related to
Theft from vendor...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/clovis.jpg" align="right" height="76" width="200">
<font size="2"><span style="font-weight: bold;">Date Reported: </span><br>2/16/08<br><br><span style="font-weight: bold;">Organization: </span><br><a target="_blank" href="http://www.cusd.com/">Clovis Unified School District</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a target="_blank" href="http://maps.google.com/maps?hl=en&amp;client=opera&amp;rls=en&amp;hs=cvf&amp;um=1&amp;ie=UTF-8&amp;q=Systematic+Automation+Inc.&amp;near=Fullerton,+CA&amp;fb=1&amp;view=text&amp;latlng=33917450,-117929410,15433360472739007456">Systematic Automation</a>* <br><font size="1"><br>*This breach is related to:<br>"<a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspxdated%202/12/08">Theft from vendor affects Modesto City Schools employees</a>" dated 2/12/08, and<br>"<a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a>" dated 2/19/08</font><br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>~4,000**<br><br><font size="1">**Over 15,000 total (and counting)</font><br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>Computer equipment was stolen from a Clovis Unified School District vendor, Systematic Automation that contained sensitive personal information belonging to employees of the district.&nbsp; Systematic Automation manages employee benefit information, and the district is the third reported organization affected by the loss.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a target="_blank" href="http://www.cbs47.tv/news/local/story.aspx?content_id=1ba0136a-9863-4073-b33c-807a493ba9fc">CBS Channel 47 News online story</a> <br><a target="_blank" href="http://www.fresnobee.com/263/story/396688.html">The Fresno Bee online story</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>CBS Channel 47 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Clovis Unified School District employees were notified that a computer stolen this week from a Fullerton company contained personal information -- including Social Security numbers -- for about 4,000 district employees.<br><br>police do not believe the intent of the burglary was to steal identity information<br><span style="font-style: italic;">[Evan] I don't know how you would determine intent based on the limited information available.&nbsp; At some point in time thieves are going to figure out that there is a heckuva lot more to gain by using the stolen information than there is in the pawning off the hardware.</span><br style="font-style: italic;"><br>Fullerton police say the computers are password protected but that doesn't mean the code can't be cracked<br><span style="font-style: italic;">[Evan] This is very true.&nbsp; Most Windows passwords can be bypassed in less than five minutes.</span><br><br>the district has recommended that employees establish fraud alerts on their credit files<br><br>The district also held two fraud-prevention seminars for employees Wednesday, with seven more planned during the next week.<br><br>Employee information for Clovis Unified and 15 other organizations was jeopardized when Systematic Automation of Fullerton was burglarized about 4:30 a.m. Monday.<br><span style="font-style: italic;">[Evan] Wow.&nbsp; 15 organizations and their employees are at risk due to one breach.&nbsp; We know of at least three; Clovis Unified School District, Los Angeles Department of Water and Power ("DWP"), and Modesto City Schools.</span><br style="font-style: italic;"><br>District employees were alerted in an e-mail about 3:30 p.m. Tuesday<br><span style="font-style: italic;">[Evan] Quick notification.&nbsp; This was a good decision on the part of district management</span><br><br>The stolen computer contained Clovis Unified employee names, addresses and salaries, as well as Social Security numbers. It did not contain birth dates or other personal information.<br><br>Systematic Automation handles the online benefits enrollment for Clovis Unified employees and publishes information on what benefits each employee receives<br><span style="font-style: italic;">[Evan] Might need to change "handles" to "handled".&nbsp; I wonder how this single breach affects Systematic Automation's business viability.</span><br style="font-style: italic;"><br>The police believe the computers contained tens of thousands of pieces of information.<br><br><span style="font-weight: bold;">Commentary:</span><br>What is there to say that hasn't already been said in the two previous postings?&nbsp; Did any of the 15 organizations audit Systematic Automation's information security practices? <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">Clovis Unified School District:</span><br>Unknown<br><span style="font-weight: bold;">Systematic Automation:</span><br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/19/dwp.aspx">L.A. Dept. of Water of Power employees exposed</a> <br>February, 2008 - <a target="_blank" href="http://breachblog.com/2008/02/12/modschools.aspx">Theft from vendor affects Modesto City Schools employees</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/02/21/clovis.aspx" type="text/javascript" charset="utf-8"></script>
]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 22:57:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/district">district</category>
      <category domain="http://securityratty.com/tag/district employees">district employees</category>
      <category domain="http://securityratty.com/tag/school district">school district</category>
      <category domain="http://securityratty.com/tag/district management">district management</category>
      <category domain="http://securityratty.com/tag/school district vendor">school district vendor</category>
      <category domain="http://securityratty.com/tag/school district employees">school district employees</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/sensitive personal information">sensitive personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/02/21/clovis.aspx">Clovis Unified School District employees receive notice</source>
    </item>
  </channel>
</rss>
